MOVEit Transfer software was discovered to be vulnerable to a potential privilege escalation and unauthorized access to the environment.
Users are recommended to take the actions mentioned below until a patch is released by the MOVEit team.
MOVEit transfer web application was vulnerable to potential SQL injection, allowing threat actors to gain unauthorized access to MOVEit’s Transfer Database.
The database can be MySQL, Microsoft SQL Server, or Azure SQL, which a remote attacker can exploit by executing SQL statements for modifying or deleting database information.
All of the MOVEit transfer versions are affected by this vulnerability. Patches are available for some of the affected versions.
| Affected Version | Fixed Version | Documentation |
| MOVEit Transfer 2023.0.0 | MOVEit Transfer 2023.0.1 | MOVEit 2023 Upgrade Documentation |
| MOVEit Transfer 2022.1.x | MOVEit Transfer 2022.1.5 | MOVEit 2022 Upgrade Documentation |
| MOVEit Transfer 2022.0.x | MOVEit Transfer 2022.0.4 | |
| MOVEit Transfer 2021.1.x | MOVEit Transfer 2021.1.4 | MOVEit 2021 Upgrade Documentation |
| MOVEit Transfer 2021.0.x | MOVEit Transfer 2021.0.6 |
In order to prevent this SQL injection vulnerability, users are requested to follow the below steps
Users are recommended to deny traffic on ports 80 (HTTP) and 443 (HTTPS) unless the patches are applied. Impacts of this step include,
Unauthorized Files and User accounts must be deleted. All logs must be reviewed for unknown IP downloads of files.
New files created on the C:\MOVEitTransfer\wwwroot\ directory must be deleted.
Service account credentials for affected systems are recommended to be reset.
Progress researchers have also provided a complete step-by-step approach to remediate this vulnerability. MOVEit transfer users are requested to apply available patches for the affected versions.
A complete report has been published, including Indicators of compromise, remediation steps, and other information.
Struggling to Apply The Security Patch in Your System? –
Try All-in-One Patch Manager Plus
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…